database-optimizer

Fail

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation link (https://jeffallan.github.io/claude-skills/skills/infrastructure/database-optimizer/) referenced in the primary instructions is flagged as malicious by automated scanners (Blacklisted).
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by ingesting untrusted data from database execution plans and query results without defined boundary markers or sanitization logic. This is critical given the skill's capability inventory includes high-privilege SQL commands such as 'ALTER SYSTEM' and 'SET GLOBAL', which could be abused if an attacker poisons the database metrics processed by the agent.
  • [METADATA_POISONING]: A discrepancy exists between the provided author identity ('emmraan') and the metadata identity ('Jeffallan') found in the skill's frontmatter and external links, suggesting potential impersonation or unauthorized provenance.
Recommendations
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 2, 2026, 01:00 AM
Security Audit — agent-trust-hub — database-optimizer